CVE-2018-3937

An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to trigger this vulnerability.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sony:snc-eb600_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb600:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sony:snc-eb630_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb630:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sony:snc-eb600b_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb600b:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:sony:snc-eb630b_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb630b:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:sony:snc-eb602r_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb602r:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:sony:snc-eb632r_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb632r:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:sony:snc-em600_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em600:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:sony:snc-em601_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em601:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:sony:snc-em630_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em630:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:sony:snc-em631_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em631:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:sony:snc-em602r_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em602r:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:sony:snc-em632r_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em632r:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:sony:snc-em602rc_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em602rc:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:sony:snc-em632rc_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em632rc:-:*:*:*:*:*:*:*

Information

Published : 2018-08-14 12:29

Updated : 2022-04-19 11:15


NVD link : CVE-2018-3937

Mitre link : CVE-2018-3937


JSON object : View

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Advertisement

dedicated server usa

Products Affected

sony

  • snc-eb632r
  • snc-eb600
  • snc-eb602r_firmware
  • snc-em600
  • snc-em601_firmware
  • snc-em601
  • snc-em632rc_firmware
  • snc-eb630_firmware
  • snc-em602r_firmware
  • snc-eb632r_firmware
  • snc-eb600_firmware
  • snc-em602rc_firmware
  • snc-eb602r
  • snc-em600_firmware
  • snc-em630
  • snc-em631_firmware
  • snc-eb630b
  • snc-em602r
  • snc-em632r_firmware
  • snc-em631
  • snc-em632r
  • snc-eb630b_firmware
  • snc-em602rc
  • snc-eb630
  • snc-eb600b
  • snc-eb600b_firmware
  • snc-em632rc
  • snc-em630_firmware